CVE-2014-1515

Firefox < 28.0 - Exposure of Sensitive Information via file: URL Processing

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2014-03/0153.html
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=945429

Scores

EPSS 0.0007
EPSS Percentile 21.1%

Details

CWE
CWE-200
Status published
Products (1)
mozilla/firefox < 28.0
Published Mar 25, 2014
Tracked Since Feb 18, 2026